Security and data handling
How we handle your statements
A plain-language account of where your files live, who can see them, what protects them and what doesn’t yet. The binding version is the Data Processing Addendum.
In short
- Your files are stored on one server in an OVHcloud data center in London, United Kingdom.
- In the app, only your account can see your files. On the server, only Alan Balcerowiak has access, and he looks at a file only if you flag it.
- No AI or language model reads your files. Parsing and matching are plain, deterministic code.
- Traffic is encrypted in transit. Some protections are not in place yet, and they are listed below.
- We hold no security certifications (no SOC 2, no ISO 27001).
Where your data lives
Statements, book exports, schedules and findings are stored on a virtual server rented from OVHcloud, in its London data center. Cloudflare sits in front of the site and the app for DNS, TLS and protection against abuse, so uploads pass through Cloudflare’s network on their way to the server. Nothing you upload is sent to Stripe, Link or anyone else.
Who can access it
- In the app: each account’s files are stored separately and are accessible only to that account.
- On the server: administrative access is limited to Alan Balcerowiak, who is bound by confidentiality. No one else works on Lapidar today. If that changes, they will be bound to confidentiality first and the DPA will be updated.
- When we look at a file: only when you flag it with “Didn’t read right?” in the app, so that the service can learn to read that layout.
- We do not sell or share your data, do not use it for our own purposes and do not combine it with other customers’ data.
How it is protected
- Encryption in transit: HTTPS/TLS between your browser and Cloudflare, and TLS again between Cloudflare and our server.
- Sign-in: email and password, or Google. Passwords are stored only as argon2id hashes, never in plain text.
- App protections: CSRF protection on every signed-in action that changes something, and limits on file size and contents.
- Backups: daily, on the same server, readable only by its administrator, each kept for up to 15 days.
- Uptime: monitored, with a public status page at status.getlapidar.com.
What is not in place yet
We would rather you know this before you upload anything:
- No two-factor login for customer accounts yet.
- No encryption of the server disk at rest.
- No off-site backups. Backups live on the same server, so losing the server would mean losing its backups as well.
- No certifications such as SOC 2 or ISO 27001, and we do not claim to make you compliant with GLBA or state insurance data security laws. We will answer your written security questions.
Please don’t upload Social Security numbers, health data or similar sensitive data; the service doesn’t need them.
Export and deletion
- You can download your findings and delete your account at any time. Deletion removes your files and data from the service straight away.
- When a subscription ends, uploads stop and your data is kept for 30 days so you can export it, then deleted.
- An account that never subscribes is deleted 30 days after it was created or last used.
- Copies in backups are overwritten within 15 days of deletion. On request we confirm deletion in writing.
Subprocessors
OVHcloud (hosting and backups, London) and Cloudflare (CDN, DNS, TLS and email routing). Email to contact@getlapidar.com is delivered to a Gmail mailbox, so please don’t email files with policyholder data; upload them in the app. The full list, with locations and terms, is in section 7 of the Data Processing Addendum. We give 30 days’ notice by email before adding or replacing a subprocessor.
If something goes wrong
If a breach affects your data, we will tell you without undue delay and in any case within 72 hours of becoming aware of it, with what happened, what data was affected and what we have done (DPA section 8). If you suspect someone has accessed your account, write to contact@getlapidar.com straight away.
Reporting a vulnerability
If you find a security problem in getlapidar.com or app.getlapidar.com, please email contact@getlapidar.com with “Security” in the subject, steps to reproduce and what you think the impact is. We will reply.
- Please test only against your own account, and don’t access, change or delete other people’s data.
- No denial-of-service, load testing or automated scanning that degrades the service.
- Give us reasonable time to fix the issue before you publish it.
We don’t run a paid bug bounty. These rules cover Lapidar only, not Cloudflare, OVHcloud or Stripe. Our contact details are also published in security.txt.